Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Sichere ProgrammierungQuantum Computing Is Getting Real. Developers Have An Opportunity.(30.09.2026 um 18:35 Uhr)
•
Sichere ProgrammierungAccelerating Spatio-Temporal Attention for Video Diffusion on TPUs(30.09.2026 um 18:36 Uhr)
••••
Sichere ProgrammierungThe Things You Used to Know by Heart(30.09.2026 um 18:23 Uhr)
•
Sichere ProgrammierungOllama Connection Refused? The 60-Second Triage(30.09.2026 um 18:24 Uhr)
•
Sichere ProgrammierungYou Might Not Need a Vector Database(30.09.2026 um 18:25 Uhr)
••
Sichere ProgrammierungI spent 6 months building a real operating system for web apps(30.09.2026 um 18:26 Uhr)
•
Sichere ProgrammierungQuantum Computing Is Getting Real. Developers Have An Opportunity.(30.09.2026 um 18:35 Uhr)
•
Sichere ProgrammierungAccelerating Spatio-Temporal Attention for Video Diffusion on TPUs(30.09.2026 um 18:36 Uhr)
••••
Sichere ProgrammierungThe Things You Used to Know by Heart(30.09.2026 um 18:23 Uhr)
•
Sichere ProgrammierungOllama Connection Refused? The 60-Second Triage(30.09.2026 um 18:24 Uhr)
•
Sichere ProgrammierungYou Might Not Need a Vector Database(30.09.2026 um 18:25 Uhr)
••
Sichere ProgrammierungI spent 6 months building a real operating system for web apps(30.09.2026 um 18:26 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

AI Agent Contracts Cannot Define Repository Acceptance

The Missing Half Of An Agent Contract Most agent contracts answer an important question: How should an agent change this repository? They can protect sensitive directories, ask for smaller diffs, require a handoff, and tell an agent…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




The Missing Half Of An Agent Contract



Most agent contracts answer an important question:




How should an agent change this repository?




They can protect sensitive directories, ask for smaller diffs, require a handoff, and tell an

agent when to stop and ask a human.



But a repository has a second question:




What must happen before this change counts as accepted?




That is not a writing-style question. It is an execution question: the setup path, the selected

services, the canonical verification lane, the execution mode, and the evidence a green result

actually carries.



An agent contract can guide edits. It cannot, by itself, define repository acceptance.





The Failure Mode



Consider an agent contract that says:




- Do not edit generated clients.
- Keep migrations small and explain them.
- Run tests before handoff.
- Ask before changing infrastructure.






Those are good contribution rules. They do not answer whether “run tests” means pnpm test, a

service-backed workflow, a container lane, or CI's actual verification closure. They do not say

whether dependencies are materialized, a database is ready, or a zero exit proves more than one

narrow check.



The dangerous outcome is a plausible handoff: the agent followed the instructions, ran a command,

and reported success. Nobody can tell whether it used the accepted path.





Ota Defines The Acceptance Path



Ota gives that operational truth a machine-readable home in ota.yaml:




tasks:
setup:
prepare:
kind: dependency_hydration
medium: package_dependencies
source:
kind: node_package_manager
manager: pnpm
mode: install
frozen_lockfile: true

verify:
command:
exe: pnpm
args: [test]
depends_on: [setup]
safe_for_agent: true

agent:
safe_tasks: [verify]
verify_after_changes: [verify]






That is not an instruction to “remember to install dependencies.” It declares one accepted setup

and verification path that Ota can inspect, dry-run, execute, and record.



An agent can discover the declared surface, then execute it through the enforced lane:




ota doctor
ota tasks --safe --use
ota run verify --agent






The important distinction is that --agent asks Ota to resolve the selected task closure before

anything starts. If the requested task, dependency, or workflow path is outside the effective safe

surface, Ota refuses it and emits a structured result rather than relying on the agent to obey

prose.






The Boundary Is Real, But Scoped



Ota does not claim to sandbox every process an agent could launch. An agent with unrestricted shell

access can still bypass Ota by not using it.



The enforcement point is the Ota runner boundary: ota run <task> --agent and, for an

agent-admitted workflow, ota up --workflow <name> --agent. That gives developers and CI fast,

inspectable execution control now. A stronger organization-wide boundary comes when CI gates and

agent harnesses consume the same contract truth.



That honesty matters. A declared safe task is useful; a runner that refuses an unsafe closure is

stronger; an org-level harness or merge gate that requires the same result is stronger again.






Two Contracts, Two Jobs



Use an agent contract for contribution behavior:




  • editing and review rules

  • sensitive files and escalation

  • coding conventions and handoff expectations



Use Ota for repository acceptance:




  • dependency hydration and setup order

  • services, readiness, tasks, and workflows

  • native or container execution selection

  • agent-admitted execution paths

  • receipts, proof boundaries, and CI drift checks



Neither replaces the other. A repository with only agent guidance still asks the agent to infer

how the software runs. A repository with only Ota can still need human collaboration rules.



The durable model is simple: let the agent contract govern edits, and let Ota govern whether the

repository was prepared, verified, and evidenced through an accepted path.






Originally posted here: https://ota.run/blog/ai-agent-contracts-cannot-define-repository-acceptance

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-103432 | apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in ge…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger • Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick